Geekom reveals multiple mini-PCs may be infected with malware hidden in a network driver — but it's now down to you to fix your PC
A malicious executable hidden within a LAN driver can track keystrokes, intercept data, and swipe passwords from Geekom mini-PCs.
Geekom, a hardware manufacturer, has disclosed that a network driver for several of its mini-PC models may have been infected with a malware called Asruex backdoor. The malicious software is capable of tracking keystrokes, stealing passwords, and intercepting data. This LAN driver, found on a legacy page, hosted the Asruex backdoor with administrator-level permissions, enabling it to monitor all activities and steal data from the user's machine.
Furthermore, the malware connects to a command and control (C2) network to communicate with hackers.
Geekom has apologized for the incident and removed the malicious software package. However, users of the A7, A8, AE7, AE8, AX7 Pro, and AX8 Pro mini-PCs are advised to perform a full system virus scan, a wipe, and reset their PCs to ensure their devices are free of the malware. The company has confirmed that the malicious driver was not preinstalled on any of its mini-PCs, and if users have not directly downloaded the malicious software from the legacy page, they should be safe.
To verify their device's safety, users are recommended to run a Windows Defender scan. To ensure maximum protection, Geekom advises performing a complete wipe and reset of Windows and installing a new Windows image directly from Microsoft's official page. In the future, it is crucial to install software and drivers only from the official support pages of the manufacturer to avoid falling victim to malicious software distributed through SEO poisoning or promoted pages.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.